CVE-2025-64262: WordPress Auto Prune Posts plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerability
Published Nov 13, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affects Auto Prune Posts: from n/a through <= 3.0.0.
Affected Software
2 affected components
ramon fincken Auto Prune Posts<=3.0.0
WordPress Auto Prune Posts<=3.0.0
Event History
Nov 13, 2025
CVE Published
via MITRE·09:24 AM
Data Sourced
via MITRE·09:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64262?
CVE-2025-64262 is classified as a moderate severity Cross-Site Request Forgery (CSRF) vulnerability.
2
How do I fix CVE-2025-64262?
To fix CVE-2025-64262, upgrade the Auto Prune Posts plugin to a version higher than 3.0.0.
3
What software is affected by CVE-2025-64262?
CVE-2025-64262 affects versions of the Auto Prune Posts plugin up to and including 3.0.0.
4
What type of vulnerability is CVE-2025-64262?
CVE-2025-64262 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is the vendor associated with CVE-2025-64262?
The vendor associated with CVE-2025-64262 is Ramon Fincken.